Muhammad I. H. Sukmana

dblp:210/3376 · also Muhammad Ihsan Haikal Sukmana · DBLP profile ↗
← Back
12ranked-venue papers
5as first author
3since 2021 · last 2021
0000-0002-1652-9895ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2021 A Feasibility Study of Log-Based Monitoring for Multi-cloud Storage Systems
Muhammad I. H. Sukmana, Justus Cöster, Wenzel Pünter, Kennedy Torkura, Feng Cheng 0002, Christoph Meinel
AINA (2)1
2021 Are You There, Moriarty? Feasibility Study of Internet-based Location for Location-based Access Control Systems
Muhammad I. H. Sukmana, Kai-Oliver Kohlen, Carl Gödecken, Pascal Schulze, Christoph Meinel
SECRYPT1
2021 Continuous auditing and threat detection in multi-cloud infrastructure
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
Comput. Secur.2
2020 A Brokerage Approach for Secure Multi-Cloud Storage Resource Management
Muhammad I. H. Sukmana, Kennedy Torkura, Sezi Dwi Sagarianti Prasetyo, Feng Cheng 0002, Christoph Meinel
SecureComm (2)1
2019 Supporting Internet-Based Location for Location-Based Access Control in Enterprise Cloud Storage Solution
Muhammad I. H. Sukmana, Kennedy Torkura, Hendrik Graupner, Ankit Chauhan, Feng Cheng 0002, Christoph Meinel
AINA1
2019 SlingShot - Automated Threat Detection and Incident Response in Multi Cloud Storage Systems
abstract
Cyber-attacks against cloud storage infrastructure e.g. Amazon S3 and Google Cloud Storage, have increased in recent years. One reason for this development is the rising adoption of cloud storage for various purposes. Robust counter-measures are therefore required to tackle these attacks especially as traditional techniques are not appropriate for the evolving attacks. We propose a two-pronged approach to address these challenges in this paper. The first approach involves dynamic snapshotting and recovery strategies to detect and partially neutralize security events. The second approach builds on the initial step by automatically correlating the generated alerts with cloud event log, to extract actionable intelligence for incident response. Thus, malicious activities are investigated, identified and eliminated. This approach is implemented in SlingShot, a cloud threat detection and incident response system which extends our earlier work - CSBAuditor, which implements the first step. The proposed techniques work together in near real time to mitigate the aforementioned security issues on Amazon Web Services (AWS) and Google Cloud Platform (GCP). We evaluated our techniques using real cloud attacks implemented with static and dynamic methods. The average Mean Time to Detect is 30 seconds for both providers, while the Mean Time to Respond is 25 minutes and 90 minutes for AWS and GCP respectively. Thus, our proposal effectively tackles contemporary cloud attacks.
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
NCA2
2019 Security Chaos Engineering for Cloud Services: Work In Progress
abstract
The majority of security breaches in cloud infrastructure in recent years are caused by human errors and misconfigured resources. Novel security models are imperative to overcome these issues. Such models must be customer-centric, continuous, not focused on traditional security paradigms like intrusion detection and adopt proactive techniques. Thus, this paper proposes CloudStrike, a cloud security system that implements the principles of Chaos Engineering to enable the aforementioned properties. Chaos Engineering is an emerging discipline employed to prevent non-security failures in cloud infrastructure via Fault Injection Testing techniques. CloudStrike employs similar techniques with a focus on injecting failures that impact security i.e. integrity, confidentiality and availability. Essentially, CloudStrike leverages the relationship between dependability and security models. Preliminary experiments provide insightful and prospective results.
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
NCA2
2018 Securing Cloud Storage Brokerage Systems Through Threat Models
abstract
Cloud storage brokerage is an abstraction aimed at providing value-added services. However, Cloud Service Brokers are challenged by several security issues including enlarged attack surfaces due to integration of disparate components and API interoperability issues. Therefore, appropriate security risk assessment methods are required to identify and evaluate these security issues, and examine the efficiency of countermeasures. A possible approach for satisfying these requirements is employment of threat modeling concepts, which have been successfully applied in traditional paradigms. In this work, we employ threat models including attack trees, attack graphs and Data Flow Diagrams against a Cloud Service Broker (CloudRAID) and analyze these security threats and risks. Furthermore, we propose an innovative technique for combining Common Vulnerability Scoring System (CVSS) and Common Configuration Scoring System (CCSS) base scores in probabilistic attack graphs to cater for configuration-based vulnerabilities which are typically leveraged for attacking cloud storage systems. This approach is necessary since existing schemes do not provide sufficient security metrics, which are imperatives for comprehensive risk assessments. We demonstrate the efficiency of our proposal by devising CCSS base scores for two common attacks against cloud storage: Cloud Storage Enumeration Attack and Cloud Storage Exploitation Attack. These metrics are then used in Attack Graph Metric-based risk assessment. Our experimental evaluation shows that our approach caters for the aforementioned gaps and provides efficient security hardening options. Therefore, our proposals can be employed to improve cloud security.
Kennedy Torkura, Muhammad I. H. Sukmana, Michael Meinig, Anne V. D. M. Kayem, Feng Cheng 0002, Hendrik Graupner, Christoph Meinel
AINA2
2018 CSBAuditor: Proactive Security Risk Analysis for Cloud Storage Broker Systems
abstract
Cloud Storage Brokers (CSB) provide seamless and concurrent access to multiple Cloud Storage Services (CSS) while abstracting cloud complexities from end-users. However, this multi-cloud strategy faces several security challenges including enlarged attack surfaces, malicious insider threats, security complexities due to integration of disparate components and API interoperability issues. Novel security approaches are imperative to tackle these security issues. Therefore, this paper proposes CS-BAuditor, a novel cloud security system that continuously audits CSB resources, to detect malicious activities and unauthorized changes e.g. bucket policy misconfigurations, and remediates these anomalies. The cloud state is maintained via a continuous snapshotting mechanism thereby ensuring fault tolerance. We adopt the principles of chaos engineering by integrating BrokerMonkey, a component that continuously injects failure into our reference CSB system, CloudRAID. Hence, CSBAuditor is continuously tested for efficiency i.e. its ability to detect the changes injected by BrokerMonkey. CSBAuditor employs security metrics for risk analysis by computing severity scores for detected vulnerabilities using the Common Configuration Scoring System, thereby overcoming the limitation of insufficient security metrics in existing cloud auditing schemes. CSBAuditor has been tested using various strategies including chaos engineering failure injection strategies. Our experimental evaluation validates the efficiency of our approach against the aforementioned security issues with a detection and recovery rate of over 96 %.
Kennedy Torkura, Muhammad I. H. Sukmana, Tim Strauss, Hendrik Graupner, Feng Cheng 0002, Christoph Meinel
NCA2
2018 A threat modeling approach for cloud storage brokerage and file sharing systems
abstract
Cloud storage brokerage systems abstract cloud storage complexities by mediating technical and business relationships between cloud stakeholders, while providing value-added services. This however raises security challenges pertaining to the integration of disparate components with sometimes conflicting security policies and architectural complexities. Assessing the security risks of these challenges is therefore important for Cloud Storage Brokers (CSBs). In this paper, we present a threat modeling schema to analyze and identify threats and risks in cloud brokerage brokerage systems. Our threat modeling schema works by generating attack trees, attack graphs, and data flow diagrams that represent the interconnections between identified security risks. Our proof-of-concept implementation employs the Common Configuration Scoring System (CCSS) to support the threat modeling schema, since current schemes lack sufficient security metrics which are imperatives for comprehensive risk assessments. We demonstrate the efficiency of our proposal by devising CCSS base scores for two attacks commonly launched against cloud storage systems: Cloud sStorage Enumeration Attack and Cloud Storage Exploitation Attack. These metrics are then combined with CVSS based metrics to assign probabilities in an Attack Tree. Thus, we show the possibility combining CVSS and CCSS for comprehensive threat modeling, and also show that our schemas can be used to improve cloud security.
Kennedy Torkura, Muhammad I. H. Sukmana, Michael Meinig, Feng Cheng 0002, Christoph Meinel, Hendrik Graupner
NOMS2
2018 CAVAS: Neutralizing Application and Container Security Vulnerabilities in the Cloud Native Era
Kennedy Torkura, Muhammad I. H. Sukmana, Feng Cheng 0002, Christoph Meinel
SecureComm (1)2
2017 Redesign cloudRAID for flexible and secure enterprise file sharing over public cloud storage
abstract
CloudRAID is a secure personal cloud storage broker that provides data availability, security, and privacy for private usage. But some of the challenges need to be resolved to use CloudRAID as an enterprise cloud storage broker solution, such as complicated key management, absence of role-based hierarchical access control, and lack of administrative oversight. In this paper we tackle these challenges and propose an enterprise version of CloudRAID called CloudRAID for Business (CfB). We combine CloudRAID with Ciphertext-Policy Attribute-Based Encryption (CP-ABE) and implement administrative oversight for monitoring activities in CfB system and multiple CSPs. Our evaluation of CfB demonstrates that it offers robust security measures through fine-grained role-based access control, scalable key management for multi-user-and-device scenarios, reduces complexity of file sharing revocation, file-level security, and administrative oversight.
Muhammad I. H. Sukmana, Kennedy Torkura, Christoph Meinel, Hendrik Graupner
SIN1